Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wv5p-gmmv-wh9v

Опубликовано: 01 июн. 2021
Источник: github
Github: Прошло ревью
CVSS4: 7.1
CVSS3: 5.5

Описание

Insertion of Sensitive Information into Log File in ansible

A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker to steal bitbucket_pipeline credentials. The highest threat from this vulnerability is to confidentiality.

Пакеты

Наименование

ansible

pip
Затронутые версииВерсия исправления

< 2.9.18

2.9.18

EPSS

Процентиль: 13%
0.00044
Низкий

7.1 High

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 4 лет назад

A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker to steal bitbucket_pipeline credentials. The highest threat from this vulnerability is to confidentiality.

CVSS3: 5
redhat
около 5 лет назад

A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker to steal bitbucket_pipeline credentials. The highest threat from this vulnerability is to confidentiality.

CVSS3: 5.5
nvd
больше 4 лет назад

A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker to steal bitbucket_pipeline credentials. The highest threat from this vulnerability is to confidentiality.

CVSS3: 5.5
msrc
больше 4 лет назад

A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker to steal bitbucket_pipeline credentials. The highest threat from this vulnerability is to confidentiality.

CVSS3: 5.5
debian
больше 4 лет назад

A flaw was found in ansible module where credentials are disclosed in ...

EPSS

Процентиль: 13%
0.00044
Низкий

7.1 High

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-532